SixLittleMonkeys aka Microcin

  • First known sample

    2017
  • Discovery

    2017
  • Current status

    Active
  • Type

    APT
  • Targeted platforms

    Windows
SIXLITTLEMONKEYS

More about the Microcin group, its tactics, techniques, procedures and tools

Learn more
  • The way of propagation

    File infection
  • Purpose/Functions

    Cyberespionage
  • Special features

    SixLittleMonkeys uses steganography to mask its malicious activity, as well as an API-like architecture in their last-stager to simplify updates of their signature Trojan.

  • Targets

    Diplomatic organizations/embassies , Government entities
  • Description

    This APT actor has been active since at least 2017 and conducts cyberespionage campaigns against government bodies and diplomatic entities. SixLittleMonkeys downloads a sophisticated backdoor on the target’s device and uses steganography to disguise their malicious activity. Their most recent campaign in February 2020 saw them utilizing a new, much more sophisticated and rare coding style—an API-like architecture.

    Additional information